Wallet and payments back end
Wallet and payments back end
Run the supporting infrastructure for a self-custodial wallet client or a stablecoin payment worker on Quake AI compute, storage, and networking. These are customer-owned workloads: you operate the back end, and Quake AI provides the compute and storage it runs on. Quake AI does not run a managed wallet, custody, or payments service, and the platform does not hold user funds or signing keys.
What this is for#
Wallet integrators, stablecoin teams, and DeFi protocol teams need a back end that talks to blockchain RPC endpoints, submits transactions, keeps an audit trail, and serves indexed history. The Tether Wallet Development Kit (WDK) is self-custodial, so signing keys live on the wallet user's device and the cloud back end does not take possession of user funds. The cloud surface is the supporting tier around that design: an RPC dependency, a transaction-submission service, audit logging, off-chain accounting, and a transaction-history database.
Quake AI runs wallet and stablecoin back ends as standard compute and storage workloads, within the platform acceptable-use policy and the compliance scope described below.
Reference architecture#
Download diagram: SVG, PNG, and PDF.
A WDK-based wallet keeps custody on the client, so the back end supports the client rather than holding keys for it. The reference shape runs on first-party primitives, keyed to the diagram above:
- RPC dependency. The back end reads chain state and broadcasts signed transactions through a blockchain RPC endpoint. Run your own nodes following RPC and blockchain nodes, or point at a managed RPC provider.
- API and submission tiers. A stateless service accepts client requests, validates them, and submits transactions. The three-tier app template separates the API web tier from the submission and accounting service. Publish the API through an API gateway for routing, authentication plugins, and rate limits, or an edge reverse proxy for a smaller HTTPS entry point.
- Postgres tier. Indexed history and off-chain accounting run on self-managed Postgres, the database VM of the three-tier app template. The self-managed PostgreSQL template covers the same tier as a standalone stack.
- Value-add variations. The monitoring variation adds a monitoring stack (Prometheus and Grafana) for service health and submission-queue depth, and the cache variation adds a Valkey queue for settlement and multi-signature work. Write an append-only audit trail to S3-compatible Object Storage with versioning, and keep working state on Block Storage.
The WDK default keeps key management on the client, so the wallet user holds the keys. A design that adds a server-side signer means software key material you manage yourself, as a customer secret under the shared responsibility model and secrets management. Quake AI has no managed HSM or remote-signer service, so a hardware-custody model brings its own HSM provider.
Stablecoin payment and settlement workers#
The off-chain pipeline behind a stablecoin payment flow runs as worker VMs on Compute: batch settlement pipelines, a multi-signature transaction queue, and off-chain accounting on self-managed Postgres. The platform has no managed database, so you run and operate the accounting layer from the self-managed PostgreSQL template. The monitoring stack template covers operator observability for the queue and the settlement workers.
The developer, analytics, and frontend workloads of a stablecoin team run here. Licensed or regulated stablecoin issuance and exchange hot-wallet hot paths run under money-transmitter licensing, MiCA, and equivalent regimes whose evidence bar is higher than the platform's SOC 2 and SOC 3 attestations, so keep that regulated settlement hot path on a platform whose attestations meet your regulator's expectations.
Keepers, liquidators, and oracle feeders#
Keepers, liquidators, and oracle feeders run as a small fleet of long-running worker VMs that watch on-chain state and submit transactions when a condition fires. The simple VM and monitoring stack templates cover the runtime and observability. These fleets typically run their own Redis-backed or Postgres-backed queue and their own scheduler, which fits the self-managed model: Quake AI does not offer a managed queue or managed scheduler.
On-chain analytics back end#
An analytics back end ingests on-chain data and serves dashboards, alerts, or APIs. It runs on Compute, with substantial Block Storage for the analytics archive and Object Storage for a cold tier. Self-managed Postgres covers the relational query layer; ClickHouse runs as a self-managed install on Compute. The platform has no managed warehouse-class database, so the query engine is one you operate.
Tether WDK and Rumble Wallet#
The Tether WDK is an open-source, self-custodial toolkit for building wallet experiences (WDK site
Rumble Wallet
Naming Tether and Rumble Wallet describes a public partnership and an open-source toolkit you can self-host. The public record covers the investment and the Rumble Wallet product; it does not mean Quake AI operates Rumble Wallet's custody, handles user funds, or that Tether endorses a Quake AI cloud product.
Services involved#
| Service | Role in this architecture | Docs |
|---|---|---|
| Compute | API tier, settlement workers, DeFi workers, analytics engine | Compute |
| Self-managed Postgres | Transaction history, off-chain accounting, analytics query layer | Self-managed PostgreSQL template |
| Object Storage | Append-only audit logs, snapshots, analytics cold tier | Object Storage |
| Block Storage | Worker state, database volumes, analytics archive | Block Storage |
| Network and self-managed edge | Public ingress, request routing, and egress controls | API gateway |
| Monitoring | Service health, queue depth, settlement-worker metrics | Monitoring stack template |
| Self-hosted RPC | Chain reads and transaction broadcast | RPC and blockchain nodes |
Get started#
- RPC and blockchain nodes: self-host the chain nodes a wallet or settlement back end reads from and broadcasts to.
- Web3 and stablecoin infrastructure: the broader pattern set for smart-contract dev, indexing, IPFS, and dapp frontends.
- Self-managed PostgreSQL template: the database tier for transaction history and off-chain accounting.
- Three-tier app template: the API, application, and database split for a wallet back end.
- Monitoring stack template: Prometheus and Grafana for worker and queue observability.
- OpenTofu template library: the validated IaC starting points for these patterns.
- Generate app credentials: the project credentials your IaC and CLI use to provision these resources.
Estimate the cost#
Monthly cost estimate
Pricing calculator ↗Sized as a custom package on a mix of shared and dedicated vCPU.
Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.
What each resource is for
2× Web tier
s1a.small · 2 shared vCPU, 2 GiB RAM, 0.5 Gbps
Serves incoming application traffic and terminates client connections.
Runs on shared CPU because the web tier scales horizontally. Add instances with web_count rather than a larger flavor.
2× App tier
m2a.large · 2 dedicated vCPU, 8 GiB RAM, 0.5 Gbps
Runs the application logic the web tier calls, on a private subnet with no public IP.
Uses general-purpose dedicated CPU for steady request handling.
Database
m2a.xlarge · 4 dedicated vCPU, 16 GiB RAM, 1 Gbps
Runs the database on a private subnet, with a dedicated data volume per instance.
Uses a memory-optimized flavor so the working set stays in RAM.
Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.
Included in baseline
s1a.small
2 shared vCPU, 2 GiB RAM, 0.5 Gbps
s1a.small
2 shared vCPU, 2 GiB RAM, 0.5 Gbps
m2a.large
2 dedicated vCPU, 8 GiB RAM, 0.5 Gbps
m2a.large
2 dedicated vCPU, 8 GiB RAM, 0.5 Gbps
m2a.xlarge
4 dedicated vCPU, 16 GiB RAM, 1 Gbps
Compute + RAM rate basis
12 vCPU + 36 GiB RAM at $29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM (regular). Totals apply the flat −$5/mo package promotion.
Block storage (150 GiB)
150 GiB at $0.08/GiB/mo
Public IP (included)
1 included with the custom package
Package promotional discount
Flat −$5.00/mo on the custom package (same promotion as named plans).
Included at no charge
These line items are zero on Quake AI. Many other providers meter them separately.
Data transfer (inbound and outbound)
Unlimited data transfer on every plan; Quake AI does not meter per-GB egress.
AWS, GCP, and Azure meter outbound transfer per GB. DigitalOcean and Hetzner include an allowance on compute plans, then charge overage.
Learn morePrivate networking
Private networks, subnets, Neutron routers, and security groups are included with the plan.
VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.
Control-plane API requests
OpenStack API calls for provisioning and management are included.
Some managed services on other clouds meter API calls or charge for premium control-plane features.
Configure your estimate
Check the add-ons you plan to deploy to build a monthly total. Nothing is selected to start, so the total below begins at the baseline.
Starting template
The required baseline, always included.
Dev/test vs production
Start on shared CPU for dev/test, then promote to dedicated for production with a flavor resize. The network, storage, and template stay the same.
Dev/test on shared CPU
Burstable s1a flavors; suited to prototyping and low or bursty load.
Production on the configured CPU
The headline estimate above; predictable steady-load performance.
Saves $198.00/mo while you build on shared CPU.
Shared flavors carry less RAM (m2a.large (8 GiB RAM) -> s1a.small (2 GiB RAM); m2a.xlarge (16 GiB RAM) -> s1a.medium (4 GiB RAM)). A resize reboots the instance; data on attached volumes persists. Size the dedicated flavor for the RAM your production workload needs.
Pricing data last validated: . For current rates, check quake.ai/pricing.
Considerations and limits#
- Custody and funds. Quake AI provides compute and storage. The platform does not hold user funds or signing authority; key material stays with the wallet user's device under the WDK self-custodial model, or with a signing service you run.
- Key management. A server-side signer means software key material that you secure yourself. The platform has no managed HSM or remote-signer service. See the shared responsibility model and secrets management.
- Card and personal data. Quake AI is not a card processor and holds no PCI-DSS attestation (compliance scope). Keep card flows and KYC or AML personal data with a compliant payment or identity vendor, as Rumble Wallet does with MoonPay for its ramps.
- No managed databases. Transaction history, accounting, and analytics run on self-managed Postgres or a self-managed engine on Compute (platform scope).
- CPU-only compute. Quake AI flavors are AMD EPYC with no GPU option (compute FAQ).
- Flat egress pricing. Quake AI bills egress at a flat rate (platform scope).
- Three US regions. The footprint is three US regions with no automatic cross-region replication (platform scope).
- Compliance ceiling. The platform holds SOC 2 Type I and Type II, with SOC 3 on request, and does not hold PCI-DSS, FedRAMP, or ISO 27001 (compliance and certifications). Your own regulatory posture, including money-transmitter licensing and MiCA where they apply, is yours to meet.